◆ Next live training: Red Blue Purple AI · Sep 1 & 3, 2026 · Attacking AI · Sep 22 & 24, 2026
HomeTrainingAttacking AI
Live Online · Sep 22 & 24, 2026

Attacking AI

Built on extensive hands-on experience, real-world consulting engagements, and deep technical research into attacking and defending AI systems. No theoretical fluff: learn precisely how AI systems can be compromised, how to assess their vulnerabilities methodically, and how to strengthen defenses against emerging threats.

If you're an offensive security professional, defender, or a technical leader looking to master the cutting edge of AI cybersecurity, this course is your next step.

$2,000 USD Sep 22 & 24, 2026 2 live sessions Intermediate Cyber, Basic AI
2
Live sessions
10-5
AM to PM, MST
$2,000
USD per seat
92
Hands-on labs
// level: intermediate cyber, basic AI · recorded & distributed to students · bulk purchases available
Attacking AI course art
What you'll learn

Skills you'll walk away able to use.

  • Threat model enterprise AI deployments across LLM and image-based systems
  • Craft prompt injection attacks against public and custom LLM endpoints
  • Distinguish fuzzing (gradient-based) from logical prompt injection
  • Jailbreak production LLMs using documented bypass methods
  • Exploit AI-integrated applications and LLM-powered APIs
  • Attack RAG systems and autonomous AI agents
  • Map findings to MITRE ATLAS and the OWASP LLM Top 10
  • Assess AI supply-chain risk across third-party tools and open-source models
  • Run AI red team engagements using current industry methodologies
  • Apply the Arcanum LLM Assessment Methodology end to end
  • Build defense bypasses with the Arcanum Prompt Injection Taxonomy
  • Deploy defensive countermeasures and AI hardening techniques

What your employer gets

  • A team member who can assess AI systems for prompt injection, jailbreaks, and agent attacks
  • A repeatable methodology for reviewing LLM-integrated applications, the Arcanum LLM Assessment Methodology
  • Coverage mapped to MITRE ATLAS and the OWASP LLM Top 10 for consistent reporting
  • The Arcanum Prompt Injection Taxonomy for testing enterprise LLM defenses
  • Course recordings the attendee can revisit and share knowledge from across the team
Hands-On Labs

The most labs of any AI course.

Attacking AI isn't slideware. You'll attack a range of deliberately vulnerable, LLM-powered applications modeled on real products: e-commerce assistants, enterprise copilots, healthcare bots, coding agents, MCP gateways, and more. Many labs come with guided walkthroughs, so you can take them home and work through them at your own pace after class.

21
Proprietary Arcanum labs, built in-house
71
Curated open-source labs
92
Total hands-on labs, the most of any course in the industry
Guided
Walkthroughs for many of the labs, to take home or do after class

// modeled on real products · yours to keep practicing after class

Course Details

What's included.

Format

// delivery
  • Hybrid of lectures, interactive discussions, and hands-on labs
  • Live training and Q&A
  • Class recordings available online
  • Certificate of completion
  • Sep 22 & 24, 10AM to 5PM MST

Prerequisites

// level
  • Intermediate cybersecurity knowledge
  • Basic understanding of AI concepts
  • Recommended level: Intermediate Cyber, Basic AI

Community

// access
  • Private Discord channel
  • Channels shared with the Red Blue Purple AI course
  • Discussion and resource sharing
Who It's For

Built for practitioners at the cutting edge.

01

Offensive Security Professionals

Learn how AI systems can be compromised and add prompt injection, jailbreaking, and AI red teaming to your toolkit.

02

Defenders

Understand the attacks methodically so you can harden AI systems and deploy defensive countermeasures that hold up.

03

Technical Leaders

Master the risks of AI adoption across your stack and bring a structured assessment methodology back to your org.

Syllabus

Thirteen modules, hands-on throughout.

Note: this syllabus is subject to updates, as AI security is a rapidly evolving field.

M01The AI Gold Rush
  • Understanding rapid AI adoption and its cybersecurity implications
  • Exploring key industries integrating AI (finance, healthcare, gaming, automotive) and their unique risks
  • Analysis of traditional security vulnerabilities prevalent in AI-driven applications (e.g., input validation, authentication, authorization)
M02Common AI Architectures and Ecosystem Risks
  • Deep dive into the AI development pipeline: model selection criteria, training procedures, deployment strategies
  • Infrastructure components overview: cloud platforms (AWS, Azure, GCP), AI-specific APIs, agentic architectures (autonomous AI agents)
  • Role and security challenges of Large Language Models (LLMs), Retrieval-Augmented Generation (RAG) systems, and autonomous AI agents
  • Risks associated with third-party AI tools, open-source models, datasets, and managing AI supply-chain security
M03Understanding AI Threat Modeling
  • Introduction to common AI security threat models (data poisoning, adversarial attacks, inference attacks)
  • Specific methodologies for threat modeling in LLM-based and image-based AI systems
  • Practical group exercise: Threat modeling a real-world enterprise AI deployment scenario
M04Introduction to Prompt Injection
  • Defining prompt injection and differentiating between fuzzing (gradient-based) and logical injection
  • Technical overview of LLM prompt processing, attention mechanisms, and model limitations
  • Basic prompt manipulation techniques (injection of malicious commands, logical constraints bypass)
  • Case studies illustrating real-world prompt injection vulnerabilities
LABHands-on Lab: Crafting Prompt Injection Attacks
  • Step-by-step guidance for crafting effective prompt injection scenarios
  • Exercises targeting various public and custom LLM endpoints
  • Discussion on practical defense mechanisms against prompt injection
M05LLM Jailbreaking for Security Professionals
  • Overview of LLM jailbreak methods
  • Review of notable jailbreak cases (ChatGPT, Claude, Gemini)
  • Practical considerations and implications of jailbreak attacks
M06Privacy and Ethical Considerations
  • Ethical hacking boundaries specific to AI
  • Privacy implications and compliance considerations (e.g., GDPR)
  • Responsible disclosure practices for AI vulnerabilities
M07AI Red Teaming Methodologies
  • Examination of current industry approaches and best practices in AI red teaming
  • Identification of key organizations and leaders driving AI security testing advancements
  • Case studies showcasing red teaming scenarios in diverse AI ecosystems
M08Attacking AI-Integrated Applications
  • Vulnerabilities and risks associated with AI-powered APIs
  • Detailed exploration of API security considerations specific to LLM-integrated systems
  • Real-world scenarios illustrating successful exploits of AI-integrated applications
M09MITRE ATLAS & OWASP AI Top Ten
  • Walkthrough of MITRE's ATLAS framework tailored for AI adversarial attacks
  • Breakdown of OWASP's Top 10 security vulnerabilities specific to LLM-based applications
M10Emerging Attack Techniques and Research
  • Overview of cutting-edge academic and industry research in AI security
  • Techniques for developing and innovating AI testing methodologies
  • Resources for continuous learning: key academic papers, blogs, and repositories
M11Defensive Countermeasures and AI Hardening
  • Strategies for strengthening AI systems against attacks
  • Defensive tooling specifically designed for AI environments
M12The Arcanum LLM Assessment Methodology
  • Introduction and step-by-step guide to Arcanum's structured methodology for assessing AI security
  • Details, best practices, and actionable guidelines for AI penetration testers
M13The Arcanum Prompt Injection Taxonomy

Finally we cover modern defenses in enterprise-based deployments of LLM enabled applications and our taxonomy to help testers devise bypasses to modern defenses. This includes going over our proprietary intent, technique, evasion, and utility format.

FINClosing Discussion & Practical Review

The course will be recorded and distributed to students after completion, so you can revisit the material on your own schedule.

Sneak Peek

Watch the talk version.

Want a taste before you enroll? Here's Jason's conference talk on attacking AI, a preview of the ideas this course takes hands-on across two live days.

Your Instructor

Taught by Jason Haddix.

JH
Jason Haddix
CEO · Lead Instructor

"Over the past few years, I've immersed myself in the intersection of offensive security and artificial intelligence, turning curiosity into actionable insights and practical methodologies. This journey has evolved into talks, research papers, and now this course. At Arcanum, our mission is to make a tangible impact on the security community with world class, modern, and accessible training."

Good to Know

Policies & access.

Refund & Access Policy

Because our training includes proprietary, cutting-edge content, all registrations are non-refundable. If you are unable to attend live sessions, full recordings will be provided following the conclusion of the course so you can access the material on your own schedule.

Class Collaboration

Participants will have access to private Discord channels shared with the "Red Blue Purple AI" course for discussion and resource sharing.

Bulk Purchases

Yes. Bulk purchases and team discounts are available. Reach out and we'll set up seats and bulk pricing for your organization.

Stay Looped In

Keep learning with the crew.

Secure your seat for Attacking AI.

Live online, September 22nd and 24th, 2026. $2,000 USD. Recordings included after the course concludes.

★★★★★ Loved by students, Read the reviews →